Avyqo
Security policy
Last updated 5 October 2026
Report vulnerabilities privately to security@avyqo.app. A machine-readable version of this policy is at /.well-known/security.txt.
Scope
avyqo.appand its subdomainsoroxia.ioand the Oroxia web app
How to report
Please include a clear description of the issue, the steps to reproduce it, the affected URL or component, and the impact you believe it has. Screenshots or a short proof of concept help us move faster. Writing from a Proton Mail address keeps your report end-to-end encrypted in transit to us.
What you can expect
- An acknowledgement within three working days.
- An initial assessment and expected timeline within ten working days.
- Updates as we work on a fix, and credit when it ships, if you would like it.
Good-faith research
We will not pursue action against researchers who act in good faith and within these guidelines:
- Only test against accounts you own or have explicit permission to use.
- Do not access, change or delete other people’s data. If you encounter it, stop and tell us.
- Do not run denial-of-service, spam or social-engineering tests, or physical attacks.
- Give us reasonable time to fix the issue before sharing it publicly.
Out of scope
- Reports from automated scanners without a demonstrated impact.
- Missing best-practice headers or settings with no practical exploit.
- Issues that require a compromised device or physical access.
We do not currently run a paid bug bounty, but we are grateful for every responsible report.